OneSpan Appoints New Chief Technology Officer

OneSpan Appoints New Chief Technology Officer

Cybersecurity firm OneSpan has announced the appointment of Ajay Keni as its new chief technology officer (CTO).

Keni will replace Benoit Grangé in the post, who will take up a new position as chief technology evangelist, in which he will “focus on sharing OneSpan’s technology vision and deep industry insights with customers, partners and the broader financial services market.”

As CTO, Keni will be tasked with guiding the expansion of OneSpan’s anti-fraud offerings to secure remote banking transactions, in particular the development and delivery of future product innovations. He has more than 20 years of experience in leading technology and product teams, and was former head of product, engineering, quality and DevOps for Oracle’s software-delivered and SaaS-delivered Identity and Access Management products.

He also played a major part in developing Oracle Cloud’s identity strategy as well leading its identity cloud service and key management cloud service.

The move is part of OneSpan’s vision to further transform the global financial services market through secure transaction solutions. Current offerings include identity verification, risk analysis, mobile application security, multi-factor authentication, e-signatures and agreement automation.

Keni commented: “OneSpan has an exciting future ahead in identity and anti-fraud technologies. There is clear market demand for OneSpan’s solutions, a strong worldwide banking customer base and a global team executing on this important and essential work in a digital world.”

Scott Clements, CEO of OneSpan, added: “OneSpan’s trusted identity strategy envisions a cloud-centric technology stack that can be deployed in private, public and hybrid environments; one that will see the company further transition toward a cloud-first offering. Ajay is a proven leader who brings experience in product innovation and in implementing open cloud technologies that can be easily integrated and deployed at scale.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

#GartnerSEC: Cybersecurity Leaders Must Start Preparing for the Next Decade

#GartnerSEC: Cybersecurity Leaders Must Start Preparing for the Next Decade

Cybersecurity leaders need to prepare for the long-term picture as well as deal with current day-to-day issues, according to Toby Bussa, VP analyst at Gartner, speaking during the Gartner Security and Risk Virtual Summit.

As we emerge from a decade of substantial change in the cybersecurity landscape, Bussa expects to see a similar evolution occur in the years up to 2030. “The last 10 years have been interesting, and we anticipate the next 10 years to be even more so,” he stated.

Bussa began by outlining the ways how the cybersecurity landscape has been radically reshaped during the past 10 years. These include advances in IT, such as the explosion in cloud services and Internet of Things (IoT) devices that have expanded the attack surface, privacy and data protection emerging as a much more prominent issue, the rise in cyber-attacks conducted by nation states and ransomware becoming more sophisticated and targeting large organizations.

With this in mind, anticipating further changes over the coming decade will be critical in preventing disruption to business performance and staying ahead of cyber-criminals.

The first expected trend outlined by Bussa is the increasing “balkanization” of the digital world in which enterprises operate. This is borne out of the competing interests of digital nationalists and digital globalists; those who want tight controls over the use of the internet and those much more comfortable with sharing data outside of boundaries.

For example, online filtering is heavily practised in certain digital boundaries, leading to scenarios where “consumers in one part of the world may be unable to access information in other parts of the world because of regulatory concerns.” Bussa added: “What the future of the internet looks like is an important backdrop for what cybersecurity leaders may need to contend with in the future.”

He also stated that technology itself may become balkanized: both in general IT and cybersecurity. This is a result of nation states increasingly developing their own technologies that are used only within certain geopolitical areas. Bussa said this phenomenon is already beginning to take effect and it “is certainly going to be a consideration for cybersecurity leaders, both to contend with the IT that’s being employed by their enterprises but also in the security technologies that they would employ.”

Another area cybersecurity leaders must consider for the coming decade is the likelihood of more regulation and regulatory complexity. Businesses are becoming increasingly digitalized, a trend further accelerated by the COVID-19 pandemic. Bussa noted that “regulators are going to continue to respond and try to understand the impact of these technology innovations on how businesses are moving forward, and this will likely be expressed as laws.”

Anticipating and preparing for these types of trends is therefore crucial to gaining an advantage over cyber-actors. In particular, he cited the need for the concept of “cyber-safety” to the come to the fore, with a broader focus on the “life, kinetic and high risk events that can harm an organization or its customers,” rather than just traditional IT security.

Organizational resiliency should be another focus for cybersecurity leaders, in light of the greater range of potential disrupters and threats, ranging from geopolitical issues to natural disasters and new regulations, according to Bussa. An example of this has been seen with the huge shift to remote working during the COVID-19 pandemic, which cyber-criminals have quickly sought to take advantage of.

Bussa concluded by stating that while many events cannot be predicted, cybersecurity leaders can take steps now to ready their organizations for future trends. However, this requires a fundamental shift in the role CISOs play. “Think about how you shift your role as a cybersecurity leader away from someone who’s going to be viewed as the scapegoat when things go wrong towards being a trusted advisor and guide to the organization by embracing a longer-term view and better understanding of what the future may hold,” he said.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Cyber-fraud Prevention Company CEO Charged with Fraud

Cyber-fraud Prevention Company CEO Charged with Fraud

The CEO of a cyber-fraud prevention company has been arrested and charged with fraud.

Adam Rogas is accused of using fraudulent financial data to obtain over $123m in financing for Las Vegas–based tech company NS8 and pocketing $17.5m of the cash for himself. 

The 43-year-old Las Vegas resident was arrested yesterday in the District of Nevada, where he is expected to appear before a judge today. 

The accused is a co-founder of NS8 and served as its CEO, CFO, and a member of its board of directors. Rogas also had primary responsibility for the company’s fundraising activities.  

In a statement released yesterday, FBI Assistant Director William F. Sweeney Jr. said: “It seems ironic that the co-founder of a company designed to prevent online fraud would engage in fraudulent activity himself, but today that’s exactly what we allege Adam Rogas did.”

A complaint unsealed today in Manhattan federal court alleges that Rogas provided NS8’s finance department with bank statements that had been altered to show tens of millions of dollars in both customer revenue and bank balances that did not exist. 

“In the period from January 2019 through February 2020, between at least approximately 40% and 95% of the purported total assets on NS8’s balance sheet were fictitious,” stated the United States Department of Justice yesterday. “In that same period, the bank statements that Rogas altered reflected over $40 million in fictitious revenue.”

In the fall of 2019 and the spring of 2020, Rogas allegedly used this fictitious revenue in fundraising rounds through which NS8 issued Series A Preferred Shares and obtained approximately $123m in investor funds.

NS8 conducted a tender offer with the funds raised from investors. Rogas received $17.5m in proceeds from that offer, personally and through a company he controlled.

Rogas is further accused of supplying falsified bank records to auditors that conducted due diligence on behalf of potential investors. 

He is charged with one count of securities fraud, one count of fraud in the offer or sale of securities, and one count of wire fraud. If convicted, he could be sentenced to up to 45 years in prison.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

#GartnerSEC: Ensuring Buy-In for Security Awareness

#GartnerSEC: Ensuring Buy-In for Security Awareness

Ensure management adoption and employee engagement in your security awareness program by delivering suitable content in an understandable language.

Speaking at the Gartner Security and Risk Virtual Summit, senior director Brian Reed said that getting investment and support for a security awareness program “depends on persuasive justification, and negotiation skills.”

Asking why gaining support is so important, Reed said that COVID-19 lockdown “provided a unique example of how security can meet the needs of a crisis and an upheaval” and it would be a shame to “waste a crisis” so companies should use this as a security awareness teaching moment.

“The majority of the cost of security awareness is going to come in people and capital, the capital spend requires spending not just on a security awareness tool, but in delivering that content,” he said. “A lot of the organizational negotiation may center around how much training an organization needs, or what the time investment you may need from participants is. Reed said this is worth considering, as well as what the rewards and consequences are.

“There is also the notion that it is always someone else’s problem and not necessarily mine,” he said, saying charts to determine roles and responsibilities can help resolve these issues from the beginning, as well as highlight skills and competencies that the organization has or is missing. He said typically people fall into one of three types:

  • People who will not do the right thing no matter what they are told
  • People who will do the right thing provided they are told what the right thing is
  • People who will do the right thing instinctively every time

Reed said the vast majority are in the middle section, and will do the right thing provided they are told what the right thing is and if they can be shown and empowered to do the right thing. The third group could also be identified as potential security champions, when other employees do not feel comfortable going to the security or IT teams.

When it comes to organizational buy-in, Reed said this is critical for when you’ve got your users on board, “and you’re accurately setting expectations.” The main ways to get buy-in across the organization include respecting the user’s time and speaking in a language that both security and management understand “as there is often a disconnect with the language being used at a business and technical level.”

Another factor is to utilize active listening techniques to demonstrate that you’ve heard the audience’s concerns, and you’re building the case for security awareness by addressing their concerns and actively pursuing resolutions.

He went on to explain that a program should be tailored for a specific country or culture, and that “seduction is a better tool than imposing security awareness programs out of fear” as you want to induce people into knowing this is can be an enabler for your business and not just another compliance training effort.

Reed concluded by saying we should “embrace and celebrate our organization’s history, and we must recognize what progress and transition looks like, and ultimately we should answer the questions of purpose and value and tie them to our security strategy.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

#GartnerSEC: Combine Security and Customer Experience Online to Tackle Fraud

#GartnerSEC: Combine Security and Customer Experience Online to Tackle Fraud

Creating trust on the internet requires the aligning of effective online fraud protection with good customer experience, according to Jonathan Care, senior director analyst at Gartner.

Speaking during the Gartner Security and Risk Virtual Summit, he observed that currently, many e-business fraud prevention teams are overly focused on loss prevention; indeed, 58% of Gartner clients have stated that fraud prevention blocks the goal of having a frictionless customer experience. Yet the two go hand-in-hand. Care said: “Many security failures and omissions can be traced to poorly designed UX.”

Trust often means something different to customers than it does for those in the cybersecurity sector, and if security measures impede user activities, it can prove a source of frustration, potentially leading to the loss of business. “Often this comes from a poorly designed security experience,” noted Care.

This includes upfront demands for sensitive security information and lack of device and channel crossover with regard to security requests. Care stated: “As a consumer, it shouldn’t matter to me if I am transacting via a web portal, a mobile app, or even interacting via the contact center.”

In addition, when online channels are targeted by hackers, this also causes “a reduction in engagement due to the loss of trust. We see a drop in traffic and therefore commerce revenue.”

It is therefore critical that online businesses find a model that combines safety with a seamless customer experience. Care believes there are three pillars to achieving this. Firstly, a commitment to prioritizing trust and safety to ensure the customer experience is slick, including with security measures like authentication.

The second is customizable customer flows, in which the risks associated with individual customers at any point in time are assessed to determine the level of security required. This can be achieved be detecting soft signals such as the use of behavioral analytics and device measurement to see whether additional authentication is needed. Care commented: “When the transaction risk is high and when the trust in the customer is low, then we need to bring in that identity proof.”

The third is the utilization of automated fraud solutions, which use analytics and machine learning to “govern a strongly defined rules base.” For example, this may include the option to redirect a customer to a manual, in-person interaction.

This requires a change in mindset, processes and technologies, according to Care. In terms of the technologies that are needed to underpin this approach, adoption of fraud detection systems that adapt to the user journey are vital, particularly those that incorporate machine learning methods, such as identity graph evaluation and analytics.

This must be done incrementally, as systems should constantly evolve to meet the changing threat landscape, as well as retain flexibility to meet new customer preferences.

Care concluded: “For consumer-facing e-businesses, trust and safety must govern the user experience and not loss prevention.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Business Owners Targeted by HMRC #COVID19 Tax Relief Scam

Business Owners Targeted by HMRC #COVID19 Tax Relief Scam

UK business owners have been targeted by a new phishing scam that attempts to gain sensitive information, including payment details, by impersonating Her Majesty’s Revenue and Customs (HMRC), according to an investigation by accountancy firm Lanop Outsourcing.

In emails purporting to be from the HMRC, recipients are told that their VAT deferral application has been rejected. This follows an initiative by the UK government to allow businesses to defer VAT payments between March and June 2020 until March 31, 2021 in order help struggling companies during the COVID-19 lockdown. At least 100 business owners have so far reported receiving this scam.

The message, which uses official HMRC branding and graphics, begins by saying “Dear customers, Your request for a deferral of VAT payments due to coronavirus (COVID-19) has been rejected… Summary of reject justification: the claimant is in arrears.”

A false document is also attached which the email claims there are “more details and a full report on your application.” It also shares a one-use password to open the document and suggests the original application has been reshared.

The victim is then redirected to a false website and asked to enter sensitive information such as email, passwords and payment details, which are then harvested by the hacker.

This is the latest in a number of phishing scams associated with financial relief measures introduced by the UK government during the COVID-19 pandemic. Others have included an attempt to steal personal and financial details of self-employed workers using the Self-Employment Income Support Scheme (SEISS) and the harvesting of data of UK workers who are expecting COVID-19 tax relief grants.

Commenting on the story, Steve Peake, UK systems engineer manager at Barracuda Networks, said: “This phishing attack is the latest in a series of HMRC-branded email scams, designed to trick business owners into handing over confidential data. With many companies struggling due to the disruption caused by the COVID-19 outbreak, we have seen a real uptake in the number of COVID-19 related attacks targeting business owners and employees. In fact, we recently observed a 667% spike in coronavirus-related spear-phishing attacks from February compared to March, during the start of the UK’s lockdown. Thus, it was only a matter of time before hackers targeted the government’s VAT deferment scheme as a new route to obtaining the bank details of unsuspecting victims.

“Socially engineered service impersonation attacks using trusted brands is unfortunately a growing practice which can be a very successful method of attack, especially when combined with the current world situation. Attackers frequently rely on this form of attack as it delivers an instant level of trust with the email recipient, with many organizations lacking the layered security approach that modern day email security requires.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

#GartnerSEC: Understand the Destination of Digital Transformation for Better Buy-In

#GartnerSEC: Understand the Destination of Digital Transformation for Better Buy-In

Security and risk leaders need to know where their plans for digital transformation are going.

Speaking in the closing keynote of the Gartner Security and Risk Virtual Summit, distinguished VP analyst Mary Mesaglio said leaders are facing four current crises in health, climate, economic and social issues, and this can lead to “transformation fatigue” as leaders are asked to accelerate digital transformation during volatile times.

“So how do we deal with this notion of fatigue with this notion that we have to double down on acceleration? The first rule is to know what we want to change into. I work with a lot of executive teams and know what they want to transform into, but that is not enough to drive the change,” Mesaglio explained.

She said the issue is the people who do the changing are led by you, and it is difficult to determine a clear and motivated endgame for them: “you’ll find the people lower down are not that clear.” Mesaglio highlighted five questions that can be asked to figure out what the transformation is, and why:

  • What are you transforming into and why?
  • Can you tell me that in under two minutes – this is a test of clarify, but are you sure what the destination is and where you’re going?
  • Can you do it using no corporate speak? Use real language and not just buzzwords
  • Can you do it in a way that would be comprehensible and motivating to the front line – to those doing the changing?
  • Would your peers say it too? Not using the same words, but with the same coherence “as you don’t want transformation schizophrenia as it leads to bad things”

She added: “It’s a high bar, but it is necessary for any change you want.” Mesaglio said that, too often, corporate messages use pictures of young, beautiful people and the message doesn’t make sense, “this is why you need a real destination and real language.

“If you are undergoing fatigue and still need to digitally accelerate, the first rule is to know what you want to transform into; this is a non-trivial exercise regardless of if you are a small or a large team,” she concluded. “Make sure you know, that there is no corporate speak as that is not going to save you and once you know that, don’t assume a big problem needs a big solution.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Pure Storage to Acquire Portworx to Expand Multi-Cloud Data Services Offering

Pure Storage to Acquire Portworx to Expand Multi-Cloud Data Services Offering

IT firm Pure Storage has entered into a definitive agreement to acquire Portworx, a Kubernetes data services platform. The deal, which is believed to be worth around $370m, is part of Pure Storage’s plan to expand into the market for multi-cloud data services to support Kubernetes and containers.

There has been substantial growth in the use of the cloud native stack to process data into value and insight in recent years, and currently 95% of new applications are developed in containers. It has also been predicted by Gartner that 85% of global businesses will be running containers in production, which is a huge rise from 35% in 2019. In order to keep up with the scaling up of multi-cloud deployments, organizations are likely to require storage services platforms to address challenges in data resiliency, mobility, security, backup and recovery.

Currently, Portworx is the Kubernetes Data Services Platform most used by Global 2000 companies to provide persistent storage, high availability, data protection, data security and cloud mobility for containers deployed in hybrid cloud architectures. Users include Carrefour, Comcast, GE Digital, Kroger, Lufthansa and T-Mobile.

Pure Storage now aims to combine this with its data-platforms and Pure Service Orchestrator software to provide a more comprehensive offering to customers.

Charles Giancarlo, chairman and CEO at Pure Storage, commented: “As forward-thinking enterprises adopt cloud native strategies to advance their business, we are thrilled to have the Portworx team and their ground breaking technology joining us at Pure to expand our success in delivering multi-cloud data services for Kubernetes. This acquisition marks a significant milestone in expanding our modern data experience to cover traditional and cloud native applications alike.”

Murli Thirumale, CEO at Portworx, added: “The traction and growth we see in our business daily shows that containers and Kubernetes are fundamental to the next-generation application architecture and thus competitiveness. We are excited for the accelerated growth and customer impact we will be able to achieve as a part of Pure.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk